Network fault detection method

By introducing a multi-module structure into the network fault detection system, acquiring and analyzing network data, performing fault detection and repeating, the problem of inability to track the network fault generation process in the prior art is solved, and the self-certification ability and stability of network fault detection are improved.

CN120075027APending Publication Date: 2025-05-30HANGZHOU EBOYLAMP ELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510145425.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art cannot track the entire process of failure when diagnosing network failures, resulting in poor self-certification capabilities of the network failure detection process.

Method used

By introducing front-end acquisition module, back-end storage module, network analysis module and data exchange module into the network fault detection system, network data is obtained and network analysis data and fault recurrence data are generated, fault detection is used for fault detection, and fault recurrence is performed through the back-end storage module to track the process of fault occurrence.

Benefits of technology

It improves the self-certification ability of the network fault detection process, can effectively track the entire process of network fault occurrence, and enhances network stability guarantee.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075027A_ABST
    Figure CN120075027A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network fault detection method, the method is applied to a network fault detection system, the system comprises a front-end acquisition module, a rear-end storage module, a network analysis module and a data exchange module, and the method comprises the following steps: the front-end acquisition module obtains network data; generating network analysis data and fault replay data, and sending the network analysis data and the fault replay data to the data exchange module; the data exchange module sends the network analysis data to the network analysis module and sends the fault replay data to the rear-end storage module; the network analysis module performs network fault detection according to the network analysis data to obtain a network fault detection result; and the back-end storage module performs fault replay according to the network fault detection result and the fault replay data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and particularly to a network fault detection method. Background Art

[0002] With the development demand of information network integration, the demand for information exchange and sharing among various equipment in the system is becoming more and more prominent. The design of the network system architecture has become more complex. The increase in various application services has also led to an increase in the types and frequencies of faults in the network environment. Network faults not only affect the user experience of customers, but may even cause the operation failure of business programs. Therefore, it is crucial to track and process network fault events in a timely and effective manner to ensure the stability of the network in a complex network system environment.

[0003] In the prior art, first, the network topology structure is defined and constructed through an analysis platform. Based on the network topology structure, data such as the configurations of various devices in the network system, mirrored network data, and device logs are obtained and sent to the analysis platform. Through the preset fault detection rules in the analysis platform combined with the fault analysis scenarios input by users, fault scenario analysis is performed on the multi-source data, and then an analysis result is obtained. However, when a network fault is diagnosed in the network environment, the entire process of the network fault generation cannot be traced, resulting in poor self-certification ability of the entire network fault detection process. Summary of the Invention

[0004] To solve the problems existing in the prior art, one or more embodiments of this specification describe a network fault detection method.

[0005] According to a first aspect, a network fault detection method is provided. The method is applied to a network fault detection system, which includes a front-end acquisition module, a back-end storage module, a network analysis module, and a data exchange module. The front-end acquisition module, the back-end storage module, and the network analysis module are communicatively connected to the data exchange module. The method includes: The front-end acquisition module obtains network data, generates network analysis data and fault replay data, and sends the network analysis data and the fault replay data to the data exchange module; The data exchange module sends the network analysis data to the network analysis module and sends the fault replay data to the back-end storage module; The network analysis module performs network fault detection based on the network analysis data to obtain a network fault detection result; The back-end storage module performs fault replay based on the network fault detection result and the fault replay data.

[0006] Preferably, the front-end acquisition module includes an FPGA unit, a first buffer unit, and a second buffer unit. The FPGA unit is used to filter the network data, the first buffer unit is used to buffer the fault replay data, and the second buffer unit is used to buffer the network analysis data.

[0007] Preferably, the front-end acquisition module obtains network data and generates network analysis data and fault replay data, including: The FPGA unit performs a first processing on the network data to obtain the fault replay data; The FPGA unit performs a second processing on the fault replay data to obtain the network analysis data.

[0008] Preferably, the first processing includes five-tuple filtering, content-level filtering, and black and white list filtering.

[0009] Preferably, the network analysis module includes a CPU unit, a first buffer unit, and a fault detection unit. The CPU unit is used to obtain the network analysis data, the first buffer unit is used to store the network analysis data, and the fault detection unit is used to perform network fault detection.

[0010] Preferably, the second processing includes classifying and extracting the fault replay data according to the data types required by the fault detection unit.

[0011] Preferably, the back-end storage module includes a storage unit, and the storage unit is used to store the fault replay data in the form of time-split files.

[0012] Preferably, the back-end storage module performs fault replay according to the network fault detection result and the fault replay data, including: Adding a fault label to the time-split file based on the network fault detection result; Performing fault replay based on the time-split file with the fault label.

[0013] Preferably, the method further includes setting a cyclic overwrite threshold and an overwrite range. The cyclic overwrite threshold is the maximum storage space of the storage unit, and the overwrite range is the ratio of the storage space cleared from the storage unit to the cyclic overwrite threshold. When the storage space occupied by the time-split file in the storage unit is equal to the cyclic overwrite threshold, the time-split file in the storage unit is cleared based on the overwrite range.

[0014] Preferably, the fault label includes a fault identifier and an identifier content. The fault identifier is used to identify the time-split file that generates the network fault, and the identifier content is used to identify the type of network fault generated by the data of the time-split file.

[0015] The beneficial effects of the present invention are as follows: 1. For the method provided in the embodiments of this specification, by storing the obtained network data in the network analysis module and the backend storage module, the data in the network analysis module is used to detect whether there is a network fault, and the data in the backend storage module is used to replay the fault scene when a network fault occurs, thereby tracking the entire process of the network fault generation, and improving the self-certification ability of the entire network fault detection process. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0017] Figure 1 is a schematic diagram of the architecture of a network fault detection system in the specific implementation of this specification; Figure 2 is a schematic diagram of the flow of a network fault detection method in the specific implementation of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application.

[0019] In the following description, the terms "first" and "second" are only for the purpose of description and cannot be construed as indicating or implying relative importance. The following description provides multiple embodiments of the present application. Different embodiments can be replaced or combined. Therefore, the present application can also be considered to include all possible combinations of the same and / or different embodiments described. Thus, if one embodiment includes features A, B, and C, and another embodiment includes features B and D, then the present application should also be considered to include embodiments containing all other possible combinations of A, B, C, and D, even though such embodiments may not be explicitly described in the following content.

[0020] The following description provides examples and does not limit the scope, applicability, or examples set forth in the claims. Changes can be made to the functions and arrangements of the described elements without departing from the scope of the content of the present application. Each example can appropriately omit, substitute, or add various processes or components. For example, the described method can be executed in a different order than the described order, and various steps can be added, omitted, or combined. In addition, the features described in some examples can be combined into other examples.

[0021] Refer to Figure 1 , Figure 1 which is a schematic architecture diagram of a network fault detection system provided by an embodiment of the present application.

[0022] As Figure 1 shown, the architecture of the network fault detection system includes a front - end acquisition module, a back - end storage module, a network analysis module, and a data exchange module. The front - end acquisition module, the back - end storage module, and the network analysis module are respectively communicatively connected to the data exchange module, so that the data exchange module can perform data transmission between any two of the front - end acquisition module, the back - end storage module, and the network analysis module.

[0023] In the embodiments of this specification, the above - mentioned front - end acquisition module, back - end storage module, network analysis module, and data exchange module can be directly or indirectly connected through wired or wireless communication methods, and the present disclosure does not limit this here.

[0024] Refer to Figure 2 , Figure 2 which shows a schematic flow diagram of a network fault detection method provided by an embodiment of this specification.

[0025] As Figure 2 shown, the network fault detection method includes the following steps: S201. The front - end acquisition module obtains network data, generates network analysis data and fault replay data, and sends the network analysis data and the fault replay data to the data exchange module.

[0026] In the embodiments of the present application, the probe can collect network data by listening to the traffic on the network interface. The network data includes five - tuple information, application - layer information, configuration information, etc. Among them, the five - tuple information includes source IP address, source port, destination IP address, destination port, and transport - layer protocol. The application - layer information represents the actual information when two devices communicate, and the configuration information represents the configuration information of each network device or network interface. The front - end acquisition module can communicate with multiple probes to obtain the network data monitored by the multiple probes. Then, the front - end acquisition module will filter the network data to obtain the network analysis data used for network fault detection and the fault replay data used for network fault replay when a network fault is detected, and send the obtained network analysis data and fault replay data to the data exchange module.

[0027] In an implementable manner, the front - end acquisition module includes an FPGA unit, a first buffer unit, and a second buffer unit. The FPGA unit is used to filter the network data, the first buffer unit is used to buffer the fault replay data, and the second buffer unit is used to buffer the network analysis data.

[0028] In the embodiments of this specification, the front-end acquisition module may be composed of multiple small units. Among them, it may include an FPGA unit and two buffer units. Since network analysis data and fault replay data need to be obtained, an FPGA unit is set to filter network data to obtain network analysis data and fault replay data, a first buffer unit is set to cache fault replay data, and a second buffer unit is set to cache network analysis data.

[0029] In an implementable manner, the front-end acquisition module obtains network data and generates network analysis data and fault replay data, including: The FPGA unit performs a first processing on the network data to obtain the fault replay data; The FPGA unit performs a second processing on the fault replay data to obtain the network analysis data.

[0030] In the embodiments of this specification, the FPGA unit first performs a first processing operation on network data to obtain two identical pieces of fault replay data, and temporarily stores one piece of fault replay data in the first buffer unit. The FPGA unit uses the other piece of fault replay data to perform a second processing operation to obtain network analysis data, and temporarily stores the network analysis data in the second buffer unit. By performing two preprocessing operations on network data by the FPGA unit, the space required to store network analysis data and fault replay data is greatly reduced, saving storage resources.

[0031] In an implementable manner, the first processing includes five-tuple filtering, content-level filtering, and black-and-white list filtering.

[0032] In the embodiments of this specification, the first processing includes five-tuple filtering, content-level filtering, and black-and-white list filtering. Among them, five-tuple filtering is to select specific network data according to the five-tuple information contained in the obtained network data. For example, select network data with the source port being port 1 from the obtained network data. Content-level filtering is to select network data according to whether the application layer information in the network data includes a preset character. Black-and-white list filtering is to select or discard some network data according to the preset black and white lists. By setting five-tuple filtering, content-level filtering, and black-and-white list filtering to eliminate some redundant information, the calculation amount of subsequent fault detection and fault replay is reduced.

[0033] In an implementable manner, the second processing includes classifying and extracting the fault replay data according to the data types required by the fault detection unit.

[0034] In the embodiments of this specification, the network analysis module includes a fault detection unit. A plurality of different network fault detection threads are preset in the fault detection unit. The secondary processing is that the FPGA unit classifies and caches according to the data types required by the network fault detection threads, and extracts key feature data for fault diagnosis, such as: only saving the source IP address and the destination IP address in the five-tuple information.

[0035] S202. The data exchange module sends the network analysis data to the network analysis module and sends the fault replay data to the backend storage module.

[0036] In the embodiments of this application, the data exchange module obtains the fault replay data from the first cache unit and sends the fault replay data to the backend storage module for storage. The data exchange module obtains the network analysis data from the second cache unit and sends the network analysis data to the network analysis module for storage.

[0037] In an implementable manner, the network analysis module includes a CPU unit, a first cache unit, and a fault detection unit. The CPU unit is used to obtain the network analysis data. The first cache unit is used to store the network analysis data. The fault detection unit is used to perform network fault detection.

[0038] In the embodiments of this specification, the network analysis module further includes a CPU unit and a first cache unit. The CPU unit is used to obtain the network analysis data and store the network analysis data in the first cache unit.

[0039] S203. The network analysis module performs network fault detection according to the network analysis data to obtain a network fault detection result.

[0040] In the embodiments of this application, the network fault detection threads pre-run in the fault detection unit of the network analysis module will perform network fault detection according to the network analysis data stored in the first cache unit, obtain a network fault detection result, and send the network fault detection result to the visualization module for display.

[0041] S204. The backend storage module performs a fault replay according to the network fault detection result and the fault replay data.

[0042] In the embodiments of the present application, when an operator receives information about a network failure (i.e., the network failure detection result) through the visualization module, the information about the network failure includes the data causing the network failure and the network failure type. When the operator needs to perform network replay, the visualization module controls the network analysis module to obtain the fault data from the backend storage module, and after obtaining the data, the FPGA unit in the front-end acquisition module sends the fault replay data into the network system to achieve the effect of fault replay.

[0043] In an implementable manner, the backend storage module includes a storage unit, and the storage unit is used to store the fault replay data in the form of time-divided files.

[0044] In the embodiments of the present application, a storage unit is provided on the backend storage module, and the fault replay data is stored in the storage unit in the form of time-divided files, namely File 1, File 2, etc. Each time-divided file represents the network data within a certain time period. As an example, the operator will preset the time threshold for dividing files. Assuming the time threshold for dividing files is 1 minute, the storage unit will store the fault replay data obtained within each time threshold for dividing files in the same time-divided file. By storing the network data within a period of time in the same time-divided file and using the time-divided file for fault replay, it is ensured that all the network data within a period of time is used during fault replay to improve the authenticity during fault replay.

[0045] In an implementable manner, the backend storage module performs fault replay based on the network failure detection result and the fault replay data, including: Attaching a fault label to the time-divided file based on the network failure detection result; Performing fault replay based on the time-divided file with the fault label.

[0046] In the embodiments of the present application, when the network analysis module detects a fault, it immediately locks the file that is currently being recorded and stored. For example, if Time-divided File 4 is being written at that time, then Time-divided File 4 is locked to prohibit deletion and a fault label description is attached (for example: Fault Data Identifier 1, Identifier Content: This data file stores XXX fault). During fault replay, the network analysis module deploys the application software to first quickly retrieve the fault data file in the backend storage module according to the fault label, and then reads the data content of the data file in the storage unit of the backend storage module and sends it to the external network in the original rhythm according to the data content through the FPGA unit to achieve network fault replay.

[0047] In an implementable manner, the method further includes setting a cyclic overwrite threshold and an overwrite range. The cyclic overwrite threshold is the maximum storage space of the storage unit, and the overwrite range is the ratio of the storage space cleared from the storage unit to the cyclic overwrite threshold. When the storage space occupied by the time-split file in the storage unit is equal to the cyclic overwrite threshold, the time-split file in the storage unit is cleared based on the overwrite range.

[0048] In the embodiments of the present application, the network fault detection method further includes setting a cyclic overwrite threshold and an overwrite range. The cyclic overwrite threshold represents the maximum storage space of the storage unit, and the overwrite range represents the ratio of the storage space cleared from the storage unit to the cyclic overwrite threshold. When the number of files stored in the storage unit reaches the cyclic overwrite threshold, if there are subsequent files to be stored, the storage unit will delete some data in the storage unit according to the overwrite range. Preferably, the first stored file is selected for deletion, and then the subsequent files are stored. As an example, if the cyclic overwrite threshold is 100G, the overwrite range is 10%, and the number of files in the storage unit has reached the cyclic overwrite threshold, when storing a file again, the storage unit will delete 10G of the content and then store the subsequent files. By setting the cyclic overwrite threshold and the overwrite range, the maximum storage space that the storage unit can occupy is set to avoid the storage unit occupying too much storage resources.

[0049] The specific embodiments of this specification have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.

Claims

1. A network fault detection method, characterized in that: The method is applied to a network fault detection system, the system comprising a front-end acquisition module, a back-end storage module, a network analysis module and a data exchange module, the front-end acquisition module, the back-end storage module and the network analysis module are communicatively connected with the data exchange module, and the method comprises: The front-end acquisition module acquires network data, generates network analysis data and fault replay data, and sends the network analysis data and the fault replay data to the data exchange module; The data exchange module sends the network analysis data to the network analysis module, and sends the fault replay data to the backend storage module; The network analysis module performs network fault detection according to the network analysis data to obtain a network fault detection result; The backend storage module performs fault replay according to the network fault detection result and the fault replay data.

2. A network fault detection method according to claim 1, characterized in that: The front-end acquisition module includes an FPGA unit, a first cache unit and a second cache unit. The FPGA unit is used to filter the network data, the first cache unit is used to cache the fault replay data, and the second cache unit is used to cache the network analysis data.

3. A network fault detection method according to claim 2, characterized in that: The front-end acquisition module acquires network data and generates network analysis data and fault replay data including: The FPGA unit processes the network data once to obtain the fault replay data; The FPGA unit performs secondary processing on the fault replay data to obtain the network analysis data.

4. A network fault detection method according to claim 3, characterized in that: The one-time processing includes five-tuple filtering, content-level filtering, and black-and-white list filtering.

5. A network fault detection method according to claim 3, characterized in that: The network analysis module includes a CPU unit, a third cache unit and a fault detection unit. The CPU unit is used to obtain the network analysis data, the third cache unit is used to store the network analysis data, and the fault detection unit is used to perform network fault detection.

6. A network fault detection method according to claim 5, characterized in that: The secondary processing includes classifying and extracting the fault replay data according to the data type required by the fault detection unit.

7. A network fault detection method according to claim 1, characterized in that: The backend storage module includes a storage unit, and the storage unit is used to store the fault replay data in the form of time-divided files.

8. A network fault detection method according to claim 7, characterized in that: The backend storage module performs fault replay according to the network fault detection result and the fault replay data, including: Based on the network fault detection result, marking the time-divided file with a fault label; Fault replay is performed based on the time-divided file with the fault tag.

9. A network fault detection method according to claim 7, characterized in that: The method also includes setting a cyclic coverage threshold and a coverage range, wherein the cyclic coverage threshold is the maximum storage space of the storage unit, and the coverage range is the ratio of the storage space cleared from the storage unit to the cyclic coverage threshold. When the storage space occupied by the time-divided files in the storage unit is equal to the cyclic coverage threshold, the time-divided files in the storage unit are cleared based on the coverage range.

10. A network fault detection method according to claim 8, characterized in that: The fault tag includes a fault identifier and identifier content. The fault identifier is used to identify the time-divided file where the network fault occurs, and the identifier content is used to identify the type of network fault generated by the time-divided file data.

Citation Information

Patent Citations

  • Method and system for storing real-time running information of intelligent substation

    CN104008214A

  • NS3 simulation system flow importing method based on Netflow

    CN106027406A

  • Intelligent substation system for urban rail transit

    CN113162235A